Use of Hard-coded Cryptographic Key
CVE-2024-45837
Summary
Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files.
- LOW
- ADJACENT_NETWORK
- LOW
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-321 - Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
References
Advisory Timeline
- Published